CVE-2026-3854
- CVSS
- —
- EPSS
- 0.014 (72.2th percentile)
- CISA KEV
- Not listed
- Exploitation
- No report
- Public exploits
- None seen
- State
- Unknown
Coverage

Wiz Research
Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854)
Details on CVE-2026-3854: A critical flaw in GitHub’s internal git infrastructure enabling RCE on GitHub.com and GitHub Enterprise Server.
What we observed
No signals recorded